arXiv (Computer Science - Cryptography and Security) • 5h
Model Context Protocol MCP: Assessing Critical Vulnerabilities in Agentic AI Infrastructure
The Model Context Protocol (MCP) is exhibiting severe security gaps due to rapid, unreviewed deployment and a reliance on probabilistic prompt-based controls. Dynamic auditing reveals that 91.8% of MCP servers lack OAuth authentication, while 687 instances expose unauthenticated shell execution. Common vulnerabilities include SQLi, SSRF, and path traversal, compounded by a 41.6% infrastructure volatility rate. Mitigation requires a shift to deterministic safeguards, specifically governed MCP proxies employing Attribute-Based Access Control (ABAC) to eliminate unauthorized tool invocation and hardware-confined keys via PKCS#11 to neutralize key exfiltration risks.